CVE-2024-53672: Arubanetworks Clearpass Policy Manager

Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system.

Affected products

  • Arubanetworks Clearpass Policy Manager: from 6.11.0, before 6.11.10 (fixed in 6.11.10); from 6.12.0, before 6.12.3 (fixed in 6.12.3)

Published 2024-12-03. Last modified 2026-06-17.